Hello,
Is it possible to restrict the NT Custom Shell without the use of NT Policies via a Domain Controller?
I am aware that .adm files, which are used to apply policies via the NT Policy Editor, basically manipulate the Registry, however is it then possible to restrict the shell of a local user for a machine not a member of a domain?
The problem to avoid is applying such changes to a local user’s registry and then not being able to switch it back if for some reason if you needed access again to the desktop.
Perhaps the use of login scripts allow such a switch? Any advice or thoughts?
Kind regards,
Jayne